Showing posts with label facebook hacked. Show all posts
Showing posts with label facebook hacked. Show all posts

Thursday, June 13, 2013

Zeus Trojan Steals Bank Account Info via Facebook

Zeus Trojan Steals Bank Account Access



A nasty Trojan virus nicknamed Zeus has been spreading quickly through social media forums like Facebook and via links to fake webpages. Once a system is compromised, the virus lays in wait until the user accesses a banking account or credit card website wherein it captures login and personal data. That information is then transferred to servers controlled by cybercriminals who sell the data or drain the victim’s bank account.


Zeus began circulating the net about six years ago, but has seen resurgence in recent months according to Internet security firm Trend Micro. The New York Times’s Nicole Perlroth (http://bits.blogs.nytimes.com/2013/06/03/malware-that-drains-your-bank-account-thriving-on-facebook/) reports that millions of computers are already infected, most of which are in the United States.

Much of this malware’s recent rapid disbursement is via links posted on Facebook. Culprits set up fake profiles and post links on popular fan pages or hack user accounts to spam links to “Friends.” In many cases, links take the user to a website where they’re prompted to purchase knock-off designer goods. After entering credit card info to complete the purchase, the victim’s credit card number (along with name and address) is sold or used to place fraudulent charges. In other cases, the website link takes the user to an infected page that installs malicious code when accessed by the unsuspecting victim.

The virus is also spread from compromised email accounts: the Trojan accesses an infected user’s contact list and then sends emails with links to malware-infected pages. The sender address is spoofed to appear as though the email was sent by the infected account, so anyone in the infected user’s contact list receives a message that appears to have come from a known source. If you ever receive a suspicious-looking email with a link or attachment, even if you recognize the sender, do not click the link. Instead, contact the sender to confirm that the email was truly sent by them.

Once infected, the Trojan virus runs silently in the background, harvesting users’ private data. In some cases, compromised systems redirect victims to dummy websites made to appear like the user’s bank or credit card account login page so that more valuable personal information (such as social security number, date of birth, address, etc) can be collected.

Many of the fraudulent links used to spread Zeus via Facebook in recent months have ended in .tk (where you’d typically see .com or .org). This domain indicates that the website is hosted via Tokelau, a small territory part of New Zealand which is, according to Jerome Segura of the anti-malware software company Malwabytes, “a hotbed for all sorts of online fraud.” As infected webpages are identified and blocked by browsers and/or antivirus software, cybercriminals simply set up a new web address, so there’s no easy way to eradicate Zeus and its variants from the net.

While Facebook has partnered with web security specialists WebSense and Web Of Trust (WOT) to identify, flag and alert users of potentially fraudulent links, it’s ultimately up to the user to exercise caution when clicking links on Facebook, in emails, or anywhere on the net. Keep in mind that links to Zeus-infected pages are cropping up all over the Web, from comments on articles or blogs to sponsored ads, so users must remain diligent about avoiding weblinks from anywhere but a completely trusted source.

In a blog posted to Trend Micro’s “TrendLabs” (http://blog.trendmicro.com/trendlabs-security-intelligence/zeuszbot-malware-shapes-up-in-2013/), Jay Yaneza recommends that you bookmark trusted websites so that you don’t inadvertently mis-type an address and end up re-directed to an imposter site. He cautions that users should avoid visiting unknown websites and keep their system’s anti-malware software up to date to reduce the risk of exposure.

Tuesday, April 16, 2013

Facebook Account Hacked? Don't Panic.

Facebook Account Hacked? Fix it now!



Anyone who's received a message from a friend's Facebook account urging them to click a link or “like” a page to "Win a Free iPad" or "Get a Free Starbucks Gift Card" knows that social media sites are prime targets for spam and data mining.  What do you do if it's YOUR account that's doing the spamming?

As soon as you discover that your account has been compromised, report it to Facebook at www.facebook.com/hacked.  Enter your password and follow the instructions to reinstate the account in your name.  You'll need to identify yourself, either through your e-mail address, phone number, Facebook user name or your name and the name of one or more of your friends.


Once you're back in control, reset your Facebook password.  Click on the little button at the top right-hand corner that looks like a gear and then choose Account Settings.  Facebook recommends that you change your password regularly (aim for every few months) to stay secure.

Choose a robust password: 7-10 digits in length, with a mix of numbers, symbols, upper-case and lower-case letters.  Be sure to change passwords on any other accounts that may have been compromised (like your email, Twitter, etc).  It’s particularly risky to use the same password across multiple accounts.  If your Facebook password is compromised, the hacker would be able to take control of your linked email account if you use the same password for both accounts.  This would allow him or her to find other logins that you have tied to that email, submit “forgot my password” reset requests and gain access to other your accounts like banking, shopping, etc.

Consider using a password management service like LastPass (www.lastpass.com, free for basic) that will create unique passwords for all your accounts and control your logins so you never have to type your username or password into a site again.

Now you need to determine how your account was compromised and plug any security holes.  The most likely culprit is a rogue app that you installed, possibly without realizing you were doing so.  For example, if you click a link to “Win a free iPad” posted (probably unwittingly) to your friend’s wall, you’ll be prompted to install an app or provide personal information in order to “register for the contest.”  Every time you approve a Facebook app you give it permissions.  This can range from access to your friends list, the ability to post to your wall, even personal information tied to your account (like your email account, linked cell phone number, etc).

To review your installed apps, click the little gear icon again and choose Privacy Settings.  Do a quick scan here to make sure your privacy settings haven’t been changed to public.  Then click on Apps in the menu bar on the left side of your screen.

Remove apps that you don’t recognize or no longer use by clicking on the X to the right of the app’s name.  For those you choose to keep, click on the name of the app to review what information the app can access and choose who sees its posts and/or notifications.  Change any visibility settings that are set to “Public” to “Friends” or “Only Me.”

Next, notify your friends that your account was compromised.  Let them know that they shouldn’t trust anything posted by your account or messages sent to them “from you” within the period that your account was out of your control.  Particularly avoid clicking links posted by your account.  If you found an app that you suspect was the culprit, let them know to check their installed apps and remove the offender.

Finally, review the information and resources provided by Facebook at https://www.facebook.com/safety/tools/ for tips to keep your account secure.

Andrea Eldridge is CEO of Nerds On Call, which offers onsite computer and laptop repair to homeowners and small businesses. Based in Redding, Calif., it has locations in five states. Contact Eldridge at www.callnerds.com/andrea.